PT-2005-1158 · Isc+1 · Bind+1

Joao Damas

·

Published

2005-01-29

·

Updated

2017-07-11

·

CVE-2005-0034

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions BIND version 9.3.0
Description The issue is caused by an "incorrect assumption" in the authvalidated validator function when DNSSEC is enabled. This allows remote attackers to cause a denial of service, resulting in the named server exiting, by sending crafted DNS packets that cause an internal consistency test to fail.
Recommendations For BIND version 9.3.0, consider disabling DNSSEC until a patch is available to prevent the denial of service. Additionally, restrict access to the authvalidated validator function to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0034

Affected Products

Bind
Bind Server